18.07.2013 Views

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 19: Auditing and Reporting<br />

Auditing on the <strong>Sidewinder</strong> <strong>G2</strong><br />

534<br />

To view a list <strong>of</strong> audit databases, enter the following command:<br />

cf audit listdb<br />

A list <strong>of</strong> audit databases appears. The database named auditdb_1 generally<br />

contains the previous day’s information. The database named<br />

auditdb_2 is generally from two days ago, and so on.<br />

Understanding audit file names<br />

The /var/log/audit.raw files contains all audit information and network probe<br />

audits contained on the <strong>Sidewinder</strong> <strong>G2</strong> in a binary format. When the file is<br />

rolled, a timestamp is appended to the file name. The easiest method for<br />

viewing the contents <strong>of</strong> the audit.raw files is to use the Admin Console’s Audit<br />

Viewing window. Refer to “Viewing audit information” on page 534.<br />

Tip: If you prefer to view the file contents via command line, refer to the<br />

showaudit and acat man pages.<br />

Audit log files use one <strong>of</strong> two file suffixes:<br />

• *.gz — This suffix is for files in compressed format. These files may be<br />

decompressed using acat or showaudit. The default file name format is<br />

audit.raw.YYYYMMDDhhmmssZZZ.YYYYMMDDhhmmssZZZ.gz, where<br />

the variables represent date and time (including time zone) <strong>of</strong> the beginning<br />

and end <strong>of</strong> that audit file’s contents. For example,<br />

20051231020000CST.20060101020000CST.gz is a file that contains audit<br />

data from December 31, 2005 at 2:00 am to January 1, 2006 at 2:00 am.<br />

• *.raw — This suffix is for files in raw audit format. These are binary<br />

formatted files that can be viewed in ASCII format using the Admin Console<br />

or command line.<br />

Viewing audit information<br />

Using the Admin Console, you can view the information contained in the audit<br />

log files. The Admin Console Audit Viewing window allows you to view audit<br />

information in real time, or for a specific time frame that you select. You can<br />

also apply filters to view specific types <strong>of</strong> audit information within a specific time<br />

frame. To view audit information using the Admin Console, follow the steps<br />

below.<br />

Using the Admin Console, select Audit and Reports > Audit Viewing. The<br />

following window appears.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!